Name | suricata-check JSON |
Version |
0.3.8b0
JSON |
| download |
home_page | None |
Summary | A command line utility to provide feedback on Suricata rules. |
upload_time | 2025-01-18 23:38:14 |
maintainer | None |
docs_url | None |
author | Koen Teuwen |
requires_python | >=3.9 |
license | EUROPEAN UNION PUBLIC LICENCE v. 1.2 EUPL © the European Union 2007, 2016 This European Union Public Licence (the ‘EUPL’) applies to the Work (as defined below) which is provided under the terms of this Licence. Any use of the Work, other than as authorised under this Licence is prohibited (to the extent such use is covered by a right of the copyright holder of the Work). The Work is provided under the terms of this Licence when the Licensor (as defined below) has placed the following notice immediately following the copyright notice for the Work: Licensed under the EUPL or has expressed by any other means his willingness to license under the EUPL. 1. Definitions In this Licence, the following terms have the following meaning: - ‘The Licence’: this Licence. - ‘The Original Work’: the work or software distributed or communicated by the Licensor under this Licence, available as Source Code and also as Executable Code as the case may be. - ‘Derivative Works’: the works or software that could be created by the Licensee, based upon the Original Work or modifications thereof. This Licence does not define the extent of modification or dependence on the Original Work required in order to classify a work as a Derivative Work; this extent is determined by copyright law applicable in the country mentioned in Article 15. - ‘The Work’: the Original Work or its Derivative Works. - ‘The Source Code’: the human-readable form of the Work which is the most convenient for people to study and modify. - ‘The Executable Code’: any code which has generally been compiled and which is meant to be interpreted by a computer as a program. - ‘The Licensor’: the natural or legal person that distributes or communicates the Work under the Licence. - ‘Contributor(s)’: any natural or legal person who modifies the Work under the Licence, or otherwise contributes to the creation of a Derivative Work. - ‘The Licensee’ or ‘You’: any natural or legal person who makes any usage of the Work under the terms of the Licence. - ‘Distribution’ or ‘Communication’: any act of selling, giving, lending, renting, distributing, communicating, transmitting, or otherwise making available, online or offline, copies of the Work or providing access to its essential functionalities at the disposal of any other natural or legal person. 2. Scope of the rights granted by the Licence The Licensor hereby grants You a worldwide, royalty-free, non-exclusive, sublicensable licence to do the following, for the duration of copyright vested in the Original Work: - use the Work in any circumstance and for all usage, - reproduce the Work, - modify the Work, and make Derivative Works based upon the Work, - communicate to the public, including the right to make available or display the Work or copies thereof to the public and perform publicly, as the case may be, the Work, - distribute the Work or copies thereof, - lend and rent the Work or copies thereof, - sublicense rights in the Work or copies thereof. Those rights can be exercised on any media, supports and formats, whether now known or later invented, as far as the applicable law permits so. In the countries where moral rights apply, the Licensor waives his right to exercise his moral right to the extent allowed by law in order to make effective the licence of the economic rights here above listed. The Licensor grants to the Licensee royalty-free, non-exclusive usage rights to any patents held by the Licensor, to the extent necessary to make use of the rights granted on the Work under this Licence. 3. Communication of the Source Code The Licensor may provide the Work either in its Source Code form, or as Executable Code. If the Work is provided as Executable Code, the Licensor provides in addition a machine-readable copy of the Source Code of the Work along with each copy of the Work that the Licensor distributes or indicates, in a notice following the copyright notice attached to the Work, a repository where the Source Code is easily and freely accessible for as long as the Licensor continues to distribute or communicate the Work. 4. Limitations on copyright Nothing in this Licence is intended to deprive the Licensee of the benefits from any exception or limitation to the exclusive rights of the rights owners in the Work, of the exhaustion of those rights or of other applicable limitations thereto. 5. Obligations of the Licensee The grant of the rights mentioned above is subject to some restrictions and obligations imposed on the Licensee. Those obligations are the following: Attribution right: The Licensee shall keep intact all copyright, patent or trademarks notices and all notices that refer to the Licence and to the disclaimer of warranties. The Licensee must include a copy of such notices and a copy of the Licence with every copy of the Work he/she distributes or communicates. The Licensee must cause any Derivative Work to carry prominent notices stating that the Work has been modified and the date of modification. Copyleft clause: If the Licensee distributes or communicates copies of the Original Works or Derivative Works, this Distribution or Communication will be done under the terms of this Licence or of a later version of this Licence unless the Original Work is expressly distributed only under this version of the Licence — for example by communicating ‘EUPL v. 1.2 only’. The Licensee (becoming Licensor) cannot offer or impose any additional terms or conditions on the Work or Derivative Work that alter or restrict the terms of the Licence. Compatibility clause: If the Licensee Distributes or Communicates Derivative Works or copies thereof based upon both the Work and another work licensed under a Compatible Licence, this Distribution or Communication can be done under the terms of this Compatible Licence. For the sake of this clause, ‘Compatible Licence’ refers to the licences listed in the appendix attached to this Licence. Should the Licensee's obligations under the Compatible Licence conflict with his/her obligations under this Licence, the obligations of the Compatible Licence shall prevail. Provision of Source Code: When distributing or communicating copies of the Work, the Licensee will provide a machine-readable copy of the Source Code or indicate a repository where this Source will be easily and freely available for as long as the Licensee continues to distribute or communicate the Work. Legal Protection: This Licence does not grant permission to use the trade names, trademarks, service marks, or names of the Licensor, except as required for reasonable and customary use in describing the origin of the Work and reproducing the content of the copyright notice. 6. Chain of Authorship The original Licensor warrants that the copyright in the Original Work granted hereunder is owned by him/her or licensed to him/her and that he/she has the power and authority to grant the Licence. Each Contributor warrants that the copyright in the modifications he/she brings to the Work are owned by him/her or licensed to him/her and that he/she has the power and authority to grant the Licence. Each time You accept the Licence, the original Licensor and subsequent Contributors grant You a licence to their contributions to the Work, under the terms of this Licence. 7. Disclaimer of Warranty The Work is a work in progress, which is continuously improved by numerous Contributors. It is not a finished work and may therefore contain defects or ‘bugs’ inherent to this type of development. For the above reason, the Work is provided under the Licence on an ‘as is’ basis and without warranties of any kind concerning the Work, including without limitation merchantability, fitness for a particular purpose, absence of defects or errors, accuracy, non-infringement of intellectual property rights other than copyright as stated in Article 6 of this Licence. This disclaimer of warranty is an essential part of the Licence and a condition for the grant of any rights to the Work. 8. Disclaimer of Liability Except in the cases of wilful misconduct or damages directly caused to natural persons, the Licensor will in no event be liable for any direct or indirect, material or moral, damages of any kind, arising out of the Licence or of the use of the Work, including without limitation, damages for loss of goodwill, work stoppage, computer failure or malfunction, loss of data or any commercial damage, even if the Licensor has been advised of the possibility of such damage. However, the Licensor will be liable under statutory product liability laws as far such laws apply to the Work. 9. Additional agreements While distributing the Work, You may choose to conclude an additional agreement, defining obligations or services consistent with this Licence. However, if accepting obligations, You may act only on your own behalf and on your sole responsibility, not on behalf of the original Licensor or any other Contributor, and only if You agree to indemnify, defend, and hold each Contributor harmless for any liability incurred by, or claims asserted against such Contributor by the fact You have accepted any warranty or additional liability. 10. Acceptance of the Licence The provisions of this Licence can be accepted by clicking on an icon ‘I agree’ placed under the bottom of a window displaying the text of this Licence or by affirming consent in any other similar way, in accordance with the rules of applicable law. Clicking on that icon indicates your clear and irrevocable acceptance of this Licence and all of its terms and conditions. Similarly, you irrevocably accept this Licence and all of its terms and conditions by exercising any rights granted to You by Article 2 of this Licence, such as the use of the Work, the creation by You of a Derivative Work or the Distribution or Communication by You of the Work or copies thereof. 11. Information to the public In case of any Distribution or Communication of the Work by means of electronic communication by You (for example, by offering to download the Work from a remote location) the distribution channel or media (for example, a website) must at least provide to the public the information requested by the applicable law regarding the Licensor, the Licence and the way it may be accessible, concluded, stored and reproduced by the Licensee. 12. Termination of the Licence The Licence and the rights granted hereunder will terminate automatically upon any breach by the Licensee of the terms of the Licence. Such a termination will not terminate the licences of any person who has received the Work from the Licensee under the Licence, provided such persons remain in full compliance with the Licence. 13. Miscellaneous Without prejudice of Article 9 above, the Licence represents the complete agreement between the Parties as to the Work. If any provision of the Licence is invalid or unenforceable under applicable law, this will not affect the validity or enforceability of the Licence as a whole. Such provision will be construed or reformed so as necessary to make it valid and enforceable. The European Commission may publish other linguistic versions or new versions of this Licence or updated versions of the Appendix, so far this is required and reasonable, without reducing the scope of the rights granted by the Licence. New versions of the Licence will be published with a unique version number. All linguistic versions of this Licence, approved by the European Commission, have identical value. Parties can take advantage of the linguistic version of their choice. 14. Jurisdiction Without prejudice to specific agreement between parties, - any litigation resulting from the interpretation of this License, arising between the European Union institutions, bodies, offices or agencies, as a Licensor, and any Licensee, will be subject to the jurisdiction of the Court of Justice of the European Union, as laid down in article 272 of the Treaty on the Functioning of the European Union, - any litigation arising between other parties and resulting from the interpretation of this License, will be subject to the exclusive jurisdiction of the competent court where the Licensor resides or conducts its primary business. 15. Applicable Law Without prejudice to specific agreement between parties, - this Licence shall be governed by the law of the European Union Member State where the Licensor has his seat, resides or has his registered office, - this licence shall be governed by Belgian law if the Licensor has no seat, residence or registered office inside a European Union Member State. Appendix ‘Compatible Licences’ according to Article 5 EUPL are: - GNU General Public License (GPL) v. 2, v. 3 - GNU Affero General Public License (AGPL) v. 3 - Open Software License (OSL) v. 2.1, v. 3.0 - Eclipse Public License (EPL) v. 1.0 - CeCILL v. 2.0, v. 2.1 - Mozilla Public Licence (MPL) v. 2 - GNU Lesser General Public Licence (LGPL) v. 2.1, v. 3 - Creative Commons Attribution-ShareAlike v. 3.0 Unported (CC BY-SA 3.0) for works other than software - European Union Public Licence (EUPL) v. 1.1, v. 1.2 - Québec Free and Open-Source Licence — Reciprocity (LiLiQ-R) or Strong Reciprocity (LiLiQ-R+). The European Commission may update this Appendix to later versions of the above licences without producing a new version of the EUPL, as long as they provide the rights granted in Article 2 of this Licence and protect the covered Source Code from exclusive appropriation. All other changes or additions to this Appendix require the production of a new EUPL version. |
keywords |
suricata
cli
rule
rules
check
checker
feedback
network intrusion detection
|
VCS |
|
bugtrack_url |
|
requirements |
setuptools
wheel
setuptools-git-versioning
click
idstools
tabulate
regex
pytest
pytest-cov
flake8
ruff
black
pyright
sphinx
sphinx-rtd-theme
myst-parser
sphinx-click
sphinx-autoapi
numpy
pandas
scikit-learn
xgboost
|
Travis-CI |
No Travis.
|
coveralls test coverage |
No coveralls.
|
# The `suricata-check` project
[![Static Badge](https://img.shields.io/badge/docs-suricata--check-blue)](https://suricata-check.teuwen.net/)
[![Python Version](https://img.shields.io/pypi/pyversions/suricata-check)](https://www.python.org)
[![PyPI](https://img.shields.io/pypi/status/suricata-check)](https://pypi.org/project/suricata-check)
[![GitHub License](https://img.shields.io/github/license/Koen1999/suricata-check)](https://github.com/Koen1999/suricata-check/blob/master/LICENSE)
[![Quick Test, Build, Lint](https://github.com/Koen1999/suricata-check/actions/workflows/python-pr.yml/badge.svg?event=push)](https://github.com/Koen1999/suricata-check/actions/workflows/python-pr.yml)
[![Extensive Test](https://github.com/Koen1999/suricata-check/actions/workflows/python-push.yml/badge.svg)](https://github.com/Koen1999/suricata-check/actions/workflows/python-push.yml)
[![Release](https://github.com/Koen1999/suricata-check/actions/workflows/python-release.yml/badge.svg)](https://github.com/Koen1999/suricata-check/actions/workflows/python-release.yml)
`suricata-check` is a command line utility to provide feedback on [Suricata](https://github.com/OISF/suricata) rules.
The tool can detect various issues including those covering syntax validity, interpretability, rule specificity, rule coverage, and efficiency.
## Features
- [Static analysis without Suricata installation for any operating system](https://suricata-check.teuwen.net/readme.html)
- [Simple CLI with options to work with any ruleset](https://suricata-check.teuwen.net/cli_usage.html)
- [Clearly documented and typed API](https://suricata-check.teuwen.net/api_usage.html)
- [CI/CD integration with GitHub and GitLab](https://suricata-check.teuwen.net/ci_cd.html)
- [Easily extendable with custom checkers](https://suricata-check.teuwen.net/checker.html)
## Installation
### From PyPI
To install `suricata-check` from [PyPI](https://pypi.org/project/suricata-check/), simply run the following command:
```bash
pip install suricata-check[performance]
```
Installation should work out-of-the-box on any Operating System (OS) and has been tested on Windows and Linux (Fedora and Ubuntu).
### From source
To install `suricata-check` from source (potentially with local modifications), simply run the following commands:
```bash
git clone https://github.com/Koen1999/suricata-check
cd suricata-check
pip install -r requirements.txt
pytest
pip install .
```
This will install `suricata-check` from source, which should be fine considering it's a pure-python package.
## Usage
After installing `suricata-check`, you can use it from the command line:
```bash
suricata-check
```
This command will look for a file ending with `.rules` in the currrent working directory, and write output to the current working directory.
More details regarding the command line interface can be found below:
```
Usage: suricata-check [OPTIONS]
The `suricata-check` command processes all rules inside a rules file and
outputs a list of detected issues.
Raises: BadParameter: If provided arguments are invalid.
RuntimeError: If no checkers could be automatically discovered.
Options:
-r, --rules TEXT Path to Suricata rules to provide check on.
[default: .]
-s, --single-rule TEXT A single Suricata rule to be checked
-o, --out TEXT Path to suricata-check output folder. [default: .]
--log-level TEXT Verbosity level for logging. Can be one of ('DEBUG',
'INFO', 'WARNING', 'ERROR') [default: INFO]
--gitlab Flag to create CodeClimate output report for GitLab
CI/CD.
--github Flag to write workflow commands to stdout for GitHub
CI/CD.
--evaluate-disabled Flag to evaluate disabled rules.
--issue-severity TEXT Verbosity level for detected issues. Can be one of
('DEBUG', 'INFO', 'WARNING', 'ERROR') [default:
INFO]
-a, --include-all Flag to indicate all checker codes should be
enabled.
-i, --include TEXT List of all checker codes to enable.
-e, --exclude TEXT List of all checker codes to disable.
--help Show this message and exit.
```
Usage of suricata-check as a module is currently not documented in detail, but the type hints and docstrings in the code should provide a decent start.
## Output
The output of `suricata-check` is collected in a folder and spread across several files. Additionally, the most important output is visible in the terminal.
`suricata-check.log` contains log messages describing the executing flow of `suricata-check` and can be useful during development, as well as to detect potential issues with parsing rules or rule files.
`suricata-check-fast.log` contains a condensed overview of all issues found by `suricata-check` in individual rules and is useful during rule engineering as feedback points to further improve rules under development.
`suricata-check-stats.log` contains a very condensed overview of all issues found by `suricata-check` across all rules and is useful when reviewing the quality of an entire ruleset.
`suricata-check.jsonl` is a jsonlines log file containing all the issues presented in `suricata-check-fast.log` together with parsed versions of _all_ rules and is useful for programatically further processing output of `suricata-check`. An example use-case could be to selectively disable rules affected by certain issues to prevent low-quality rules inducing additional workload in Security Operations Centers.
## Issue codes
`suricata-check` employs various checkers, each emitting one or more _issue codes_.
The issue codes are grouped into several ranges, depending on the category of the checker.
Each issue group is explained in detail below.
For details regarding specific issues, we recommend you check the message of the issue as well as the test example rules under `tests/checkers`.
### Overview
| Issue identifier format | Description |
| ----------------------- | ----------------------------------------------------------- |
| M000 | Rules pertaining to the detection of valid Suricata syntax. |
| S000 | Rules derived from the Suricata Style Guide. |
| P000,Q000 | Rules based [Ruling the Unruly](https://doi.org/10.1145/3708821.3710823). |
| C000 | Rules based on community issues, such as this GitHub. |
### Mandatory issues
Rules starting with prefix _M_ indicate issues pertaining to the validity of Suricata rules.
Rules with _M_-type issues will most probably not be used by Suricata due to invalid syntax or missing fields.
Not all invalid rules wlll be reported through _M_-type issues as some rules can simply not be parsed to the point where these issues are detected.
Instead, you can detect these rules through the `ERROR` messages in `suricata-check.log`.
### Suricata Style Guide issues
Rules starting with prefix _S_ indicate issues pertaining to the adherence to the [Suricata Style Guide](https://github.com/sidallocation/suricata-style-guide).
Rules with _S_-type issues are likely to hint on interpretability or efficiency issues.
### Principle issues
Rules starting with prefix _P_ indicate issues relating to rule design principles posed in the [Ruling the Unruly](https://doi.org/10.1145/3708821.3710823) paper.
Rules with _P_-type issues can relate to a specificity and coverage.
### Community issues
Rules starting with prefix _C_ indicate issues posed by the community and are an extension on top of the other issue groups.
Rules with _C_-type issues can relate to a wide variety of issues.
You can propose your own community type issues that should be checked for in the [issues](https://github.com/Koen1999/suricata-check/issues) section.
## Contributing
If you would like to contribute, please check out [CONTRIBUTING.md](https://github.com/Koen1999/suricata-check/blob/master/CONTRIBUTING.md) some helpful suggestions and instructions.
## License
This project is licensed under the [European Union Public Licence (EUPL)](https://github.com/Koen1999/suricata-check/blob/master/LICENSE).
Note that extensions may be licensed under another license as detailed in [CONTRIBUTING.md](https://github.com/Koen1999/suricata-check/blob/master/CONTRIBUTING.md).
For example, the [suricata-check-extension-example](https://github.com/Koen1999/suricata-check-extension-example) project is licensed under the [Apache 2.0 license](https://github.com/Koen1999/suricata-check-extension-example/blob/master/LICENSE).
## Citations
If you use the source code, the tool, or otherwise draw from this work, please cite the following paper:
**Koen T. W. Teuwen, Tom Mulders, Emmanuele Zambon, and Luca Allodi. 2025. Ruling the Unruly: Designing Effective, Low-Noise Network Intrusion Detection Rules for Security Operations Centers. In ACM Asia Conference on Computer and Communications Security (ASIA CCS ’25), August 25–29, 2025, Hanoi, Vietnam. ACM, New York, NY, USA, 14 pages. [https://doi.org/10.1145/3708821.3710823](https://doi.org/10.1145/3708821.3710823)**
Raw data
{
"_id": null,
"home_page": null,
"name": "suricata-check",
"maintainer": null,
"docs_url": null,
"requires_python": ">=3.9",
"maintainer_email": null,
"keywords": "suricata, cli, rule, rules, check, checker, feedback, network intrusion detection",
"author": "Koen Teuwen",
"author_email": null,
"download_url": "https://files.pythonhosted.org/packages/0d/42/b06f8d0d69a66fc6c76a50094986607607d7b6542804bff6e0bb1a07ee36/suricata_check-0.3.8b0.tar.gz",
"platform": null,
"description": "# The `suricata-check` project\n\n[![Static Badge](https://img.shields.io/badge/docs-suricata--check-blue)](https://suricata-check.teuwen.net/)\n[![Python Version](https://img.shields.io/pypi/pyversions/suricata-check)](https://www.python.org)\n[![PyPI](https://img.shields.io/pypi/status/suricata-check)](https://pypi.org/project/suricata-check)\n[![GitHub License](https://img.shields.io/github/license/Koen1999/suricata-check)](https://github.com/Koen1999/suricata-check/blob/master/LICENSE)\n\n[![Quick Test, Build, Lint](https://github.com/Koen1999/suricata-check/actions/workflows/python-pr.yml/badge.svg?event=push)](https://github.com/Koen1999/suricata-check/actions/workflows/python-pr.yml)\n[![Extensive Test](https://github.com/Koen1999/suricata-check/actions/workflows/python-push.yml/badge.svg)](https://github.com/Koen1999/suricata-check/actions/workflows/python-push.yml)\n[![Release](https://github.com/Koen1999/suricata-check/actions/workflows/python-release.yml/badge.svg)](https://github.com/Koen1999/suricata-check/actions/workflows/python-release.yml)\n\n\n`suricata-check` is a command line utility to provide feedback on [Suricata](https://github.com/OISF/suricata) rules.\nThe tool can detect various issues including those covering syntax validity, interpretability, rule specificity, rule coverage, and efficiency.\n\n## Features\n\n- [Static analysis without Suricata installation for any operating system](https://suricata-check.teuwen.net/readme.html)\n- [Simple CLI with options to work with any ruleset](https://suricata-check.teuwen.net/cli_usage.html)\n- [Clearly documented and typed API](https://suricata-check.teuwen.net/api_usage.html)\n- [CI/CD integration with GitHub and GitLab](https://suricata-check.teuwen.net/ci_cd.html)\n- [Easily extendable with custom checkers](https://suricata-check.teuwen.net/checker.html)\n\n## Installation\n\n### From PyPI\n\nTo install `suricata-check` from [PyPI](https://pypi.org/project/suricata-check/), simply run the following command:\n\n```bash\npip install suricata-check[performance]\n```\n\nInstallation should work out-of-the-box on any Operating System (OS) and has been tested on Windows and Linux (Fedora and Ubuntu).\n\n### From source\n\nTo install `suricata-check` from source (potentially with local modifications), simply run the following commands:\n\n```bash\ngit clone https://github.com/Koen1999/suricata-check\ncd suricata-check\npip install -r requirements.txt\npytest\npip install .\n```\n\nThis will install `suricata-check` from source, which should be fine considering it's a pure-python package.\n\n## Usage\n\nAfter installing `suricata-check`, you can use it from the command line:\n\n```bash\nsuricata-check\n```\n\nThis command will look for a file ending with `.rules` in the currrent working directory, and write output to the current working directory.\n\nMore details regarding the command line interface can be found below:\n\n```\nUsage: suricata-check [OPTIONS]\n\n\n The `suricata-check` command processes all rules inside a rules file and\n outputs a list of detected issues.\n\n Raises: BadParameter: If provided arguments are invalid.\n\n RuntimeError: If no checkers could be automatically discovered.\n\nOptions:\n -r, --rules TEXT Path to Suricata rules to provide check on.\n [default: .]\n -s, --single-rule TEXT A single Suricata rule to be checked\n -o, --out TEXT Path to suricata-check output folder. [default: .]\n --log-level TEXT Verbosity level for logging. Can be one of ('DEBUG',\n 'INFO', 'WARNING', 'ERROR') [default: INFO]\n --gitlab Flag to create CodeClimate output report for GitLab\n CI/CD.\n --github Flag to write workflow commands to stdout for GitHub\n CI/CD.\n --evaluate-disabled Flag to evaluate disabled rules.\n --issue-severity TEXT Verbosity level for detected issues. Can be one of\n ('DEBUG', 'INFO', 'WARNING', 'ERROR') [default:\n INFO]\n -a, --include-all Flag to indicate all checker codes should be\n enabled.\n -i, --include TEXT List of all checker codes to enable.\n -e, --exclude TEXT List of all checker codes to disable.\n --help Show this message and exit.\n```\n\nUsage of suricata-check as a module is currently not documented in detail, but the type hints and docstrings in the code should provide a decent start.\n\n## Output\n\nThe output of `suricata-check` is collected in a folder and spread across several files. Additionally, the most important output is visible in the terminal.\n\n`suricata-check.log` contains log messages describing the executing flow of `suricata-check` and can be useful during development, as well as to detect potential issues with parsing rules or rule files.\n\n`suricata-check-fast.log` contains a condensed overview of all issues found by `suricata-check` in individual rules and is useful during rule engineering as feedback points to further improve rules under development.\n\n`suricata-check-stats.log` contains a very condensed overview of all issues found by `suricata-check` across all rules and is useful when reviewing the quality of an entire ruleset.\n\n`suricata-check.jsonl` is a jsonlines log file containing all the issues presented in `suricata-check-fast.log` together with parsed versions of _all_ rules and is useful for programatically further processing output of `suricata-check`. An example use-case could be to selectively disable rules affected by certain issues to prevent low-quality rules inducing additional workload in Security Operations Centers.\n\n## Issue codes\n\n`suricata-check` employs various checkers, each emitting one or more _issue codes_.\nThe issue codes are grouped into several ranges, depending on the category of the checker.\nEach issue group is explained in detail below.\nFor details regarding specific issues, we recommend you check the message of the issue as well as the test example rules under `tests/checkers`.\n\n### Overview\n\n| Issue identifier format | Description |\n| ----------------------- | ----------------------------------------------------------- |\n| M000 | Rules pertaining to the detection of valid Suricata syntax. |\n| S000 | Rules derived from the Suricata Style Guide. |\n| P000,Q000 | Rules based [Ruling the Unruly](https://doi.org/10.1145/3708821.3710823). |\n| C000 | Rules based on community issues, such as this GitHub. |\n\n### Mandatory issues\n\nRules starting with prefix _M_ indicate issues pertaining to the validity of Suricata rules.\nRules with _M_-type issues will most probably not be used by Suricata due to invalid syntax or missing fields.\n\nNot all invalid rules wlll be reported through _M_-type issues as some rules can simply not be parsed to the point where these issues are detected.\nInstead, you can detect these rules through the `ERROR` messages in `suricata-check.log`.\n\n### Suricata Style Guide issues\n\nRules starting with prefix _S_ indicate issues pertaining to the adherence to the [Suricata Style Guide](https://github.com/sidallocation/suricata-style-guide).\nRules with _S_-type issues are likely to hint on interpretability or efficiency issues.\n\n### Principle issues\n\nRules starting with prefix _P_ indicate issues relating to rule design principles posed in the [Ruling the Unruly](https://doi.org/10.1145/3708821.3710823) paper.\nRules with _P_-type issues can relate to a specificity and coverage.\n\n### Community issues\n\nRules starting with prefix _C_ indicate issues posed by the community and are an extension on top of the other issue groups.\nRules with _C_-type issues can relate to a wide variety of issues.\nYou can propose your own community type issues that should be checked for in the [issues](https://github.com/Koen1999/suricata-check/issues) section.\n\n## Contributing\n\nIf you would like to contribute, please check out [CONTRIBUTING.md](https://github.com/Koen1999/suricata-check/blob/master/CONTRIBUTING.md) some helpful suggestions and instructions.\n\n## License\n\nThis project is licensed under the [European Union Public Licence (EUPL)](https://github.com/Koen1999/suricata-check/blob/master/LICENSE).\n\nNote that extensions may be licensed under another license as detailed in [CONTRIBUTING.md](https://github.com/Koen1999/suricata-check/blob/master/CONTRIBUTING.md).\nFor example, the [suricata-check-extension-example](https://github.com/Koen1999/suricata-check-extension-example) project is licensed under the [Apache 2.0 license](https://github.com/Koen1999/suricata-check-extension-example/blob/master/LICENSE).\n\n## Citations\nIf you use the source code, the tool, or otherwise draw from this work, please cite the following paper:\n\n**Koen T. W. Teuwen, Tom Mulders, Emmanuele Zambon, and Luca Allodi. 2025. Ruling the Unruly: Designing Effective, Low-Noise Network Intrusion Detection Rules for Security Operations Centers. In ACM Asia Conference on Computer and Communications Security (ASIA CCS \u201925), August 25\u201329, 2025, Hanoi, Vietnam. ACM, New York, NY, USA, 14 pages. [https://doi.org/10.1145/3708821.3710823](https://doi.org/10.1145/3708821.3710823)**\n\n",
"bugtrack_url": null,
"license": "EUROPEAN UNION PUBLIC LICENCE v. 1.2 EUPL \u00a9 the European Union 2007, 2016 This European Union Public Licence (the \u2018EUPL\u2019) applies to the Work (as defined below) which is provided under the terms of this Licence. Any use of the Work, other than as authorised under this Licence is prohibited (to the extent such use is covered by a right of the copyright holder of the Work). The Work is provided under the terms of this Licence when the Licensor (as defined below) has placed the following notice immediately following the copyright notice for the Work: Licensed under the EUPL or has expressed by any other means his willingness to license under the EUPL. 1. Definitions In this Licence, the following terms have the following meaning: - \u2018The Licence\u2019: this Licence. - \u2018The Original Work\u2019: the work or software distributed or communicated by the Licensor under this Licence, available as Source Code and also as Executable Code as the case may be. - \u2018Derivative Works\u2019: the works or software that could be created by the Licensee, based upon the Original Work or modifications thereof. This Licence does not define the extent of modification or dependence on the Original Work required in order to classify a work as a Derivative Work; this extent is determined by copyright law applicable in the country mentioned in Article 15. - \u2018The Work\u2019: the Original Work or its Derivative Works. - \u2018The Source Code\u2019: the human-readable form of the Work which is the most convenient for people to study and modify. - \u2018The Executable Code\u2019: any code which has generally been compiled and which is meant to be interpreted by a computer as a program. - \u2018The Licensor\u2019: the natural or legal person that distributes or communicates the Work under the Licence. - \u2018Contributor(s)\u2019: any natural or legal person who modifies the Work under the Licence, or otherwise contributes to the creation of a Derivative Work. - \u2018The Licensee\u2019 or \u2018You\u2019: any natural or legal person who makes any usage of the Work under the terms of the Licence. - \u2018Distribution\u2019 or \u2018Communication\u2019: any act of selling, giving, lending, renting, distributing, communicating, transmitting, or otherwise making available, online or offline, copies of the Work or providing access to its essential functionalities at the disposal of any other natural or legal person. 2. Scope of the rights granted by the Licence The Licensor hereby grants You a worldwide, royalty-free, non-exclusive, sublicensable licence to do the following, for the duration of copyright vested in the Original Work: - use the Work in any circumstance and for all usage, - reproduce the Work, - modify the Work, and make Derivative Works based upon the Work, - communicate to the public, including the right to make available or display the Work or copies thereof to the public and perform publicly, as the case may be, the Work, - distribute the Work or copies thereof, - lend and rent the Work or copies thereof, - sublicense rights in the Work or copies thereof. Those rights can be exercised on any media, supports and formats, whether now known or later invented, as far as the applicable law permits so. In the countries where moral rights apply, the Licensor waives his right to exercise his moral right to the extent allowed by law in order to make effective the licence of the economic rights here above listed. The Licensor grants to the Licensee royalty-free, non-exclusive usage rights to any patents held by the Licensor, to the extent necessary to make use of the rights granted on the Work under this Licence. 3. Communication of the Source Code The Licensor may provide the Work either in its Source Code form, or as Executable Code. If the Work is provided as Executable Code, the Licensor provides in addition a machine-readable copy of the Source Code of the Work along with each copy of the Work that the Licensor distributes or indicates, in a notice following the copyright notice attached to the Work, a repository where the Source Code is easily and freely accessible for as long as the Licensor continues to distribute or communicate the Work. 4. Limitations on copyright Nothing in this Licence is intended to deprive the Licensee of the benefits from any exception or limitation to the exclusive rights of the rights owners in the Work, of the exhaustion of those rights or of other applicable limitations thereto. 5. Obligations of the Licensee The grant of the rights mentioned above is subject to some restrictions and obligations imposed on the Licensee. Those obligations are the following: Attribution right: The Licensee shall keep intact all copyright, patent or trademarks notices and all notices that refer to the Licence and to the disclaimer of warranties. The Licensee must include a copy of such notices and a copy of the Licence with every copy of the Work he/she distributes or communicates. The Licensee must cause any Derivative Work to carry prominent notices stating that the Work has been modified and the date of modification. Copyleft clause: If the Licensee distributes or communicates copies of the Original Works or Derivative Works, this Distribution or Communication will be done under the terms of this Licence or of a later version of this Licence unless the Original Work is expressly distributed only under this version of the Licence \u2014 for example by communicating \u2018EUPL v. 1.2 only\u2019. The Licensee (becoming Licensor) cannot offer or impose any additional terms or conditions on the Work or Derivative Work that alter or restrict the terms of the Licence. Compatibility clause: If the Licensee Distributes or Communicates Derivative Works or copies thereof based upon both the Work and another work licensed under a Compatible Licence, this Distribution or Communication can be done under the terms of this Compatible Licence. For the sake of this clause, \u2018Compatible Licence\u2019 refers to the licences listed in the appendix attached to this Licence. Should the Licensee's obligations under the Compatible Licence conflict with his/her obligations under this Licence, the obligations of the Compatible Licence shall prevail. Provision of Source Code: When distributing or communicating copies of the Work, the Licensee will provide a machine-readable copy of the Source Code or indicate a repository where this Source will be easily and freely available for as long as the Licensee continues to distribute or communicate the Work. Legal Protection: This Licence does not grant permission to use the trade names, trademarks, service marks, or names of the Licensor, except as required for reasonable and customary use in describing the origin of the Work and reproducing the content of the copyright notice. 6. Chain of Authorship The original Licensor warrants that the copyright in the Original Work granted hereunder is owned by him/her or licensed to him/her and that he/she has the power and authority to grant the Licence. Each Contributor warrants that the copyright in the modifications he/she brings to the Work are owned by him/her or licensed to him/her and that he/she has the power and authority to grant the Licence. Each time You accept the Licence, the original Licensor and subsequent Contributors grant You a licence to their contributions to the Work, under the terms of this Licence. 7. Disclaimer of Warranty The Work is a work in progress, which is continuously improved by numerous Contributors. It is not a finished work and may therefore contain defects or \u2018bugs\u2019 inherent to this type of development. For the above reason, the Work is provided under the Licence on an \u2018as is\u2019 basis and without warranties of any kind concerning the Work, including without limitation merchantability, fitness for a particular purpose, absence of defects or errors, accuracy, non-infringement of intellectual property rights other than copyright as stated in Article 6 of this Licence. This disclaimer of warranty is an essential part of the Licence and a condition for the grant of any rights to the Work. 8. Disclaimer of Liability Except in the cases of wilful misconduct or damages directly caused to natural persons, the Licensor will in no event be liable for any direct or indirect, material or moral, damages of any kind, arising out of the Licence or of the use of the Work, including without limitation, damages for loss of goodwill, work stoppage, computer failure or malfunction, loss of data or any commercial damage, even if the Licensor has been advised of the possibility of such damage. However, the Licensor will be liable under statutory product liability laws as far such laws apply to the Work. 9. Additional agreements While distributing the Work, You may choose to conclude an additional agreement, defining obligations or services consistent with this Licence. However, if accepting obligations, You may act only on your own behalf and on your sole responsibility, not on behalf of the original Licensor or any other Contributor, and only if You agree to indemnify, defend, and hold each Contributor harmless for any liability incurred by, or claims asserted against such Contributor by the fact You have accepted any warranty or additional liability. 10. Acceptance of the Licence The provisions of this Licence can be accepted by clicking on an icon \u2018I agree\u2019 placed under the bottom of a window displaying the text of this Licence or by affirming consent in any other similar way, in accordance with the rules of applicable law. Clicking on that icon indicates your clear and irrevocable acceptance of this Licence and all of its terms and conditions. Similarly, you irrevocably accept this Licence and all of its terms and conditions by exercising any rights granted to You by Article 2 of this Licence, such as the use of the Work, the creation by You of a Derivative Work or the Distribution or Communication by You of the Work or copies thereof. 11. Information to the public In case of any Distribution or Communication of the Work by means of electronic communication by You (for example, by offering to download the Work from a remote location) the distribution channel or media (for example, a website) must at least provide to the public the information requested by the applicable law regarding the Licensor, the Licence and the way it may be accessible, concluded, stored and reproduced by the Licensee. 12. Termination of the Licence The Licence and the rights granted hereunder will terminate automatically upon any breach by the Licensee of the terms of the Licence. Such a termination will not terminate the licences of any person who has received the Work from the Licensee under the Licence, provided such persons remain in full compliance with the Licence. 13. Miscellaneous Without prejudice of Article 9 above, the Licence represents the complete agreement between the Parties as to the Work. If any provision of the Licence is invalid or unenforceable under applicable law, this will not affect the validity or enforceability of the Licence as a whole. Such provision will be construed or reformed so as necessary to make it valid and enforceable. The European Commission may publish other linguistic versions or new versions of this Licence or updated versions of the Appendix, so far this is required and reasonable, without reducing the scope of the rights granted by the Licence. New versions of the Licence will be published with a unique version number. All linguistic versions of this Licence, approved by the European Commission, have identical value. Parties can take advantage of the linguistic version of their choice. 14. Jurisdiction Without prejudice to specific agreement between parties, - any litigation resulting from the interpretation of this License, arising between the European Union institutions, bodies, offices or agencies, as a Licensor, and any Licensee, will be subject to the jurisdiction of the Court of Justice of the European Union, as laid down in article 272 of the Treaty on the Functioning of the European Union, - any litigation arising between other parties and resulting from the interpretation of this License, will be subject to the exclusive jurisdiction of the competent court where the Licensor resides or conducts its primary business. 15. Applicable Law Without prejudice to specific agreement between parties, - this Licence shall be governed by the law of the European Union Member State where the Licensor has his seat, resides or has his registered office, - this licence shall be governed by Belgian law if the Licensor has no seat, residence or registered office inside a European Union Member State. Appendix \u2018Compatible Licences\u2019 according to Article 5 EUPL are: - GNU General Public License (GPL) v. 2, v. 3 - GNU Affero General Public License (AGPL) v. 3 - Open Software License (OSL) v. 2.1, v. 3.0 - Eclipse Public License (EPL) v. 1.0 - CeCILL v. 2.0, v. 2.1 - Mozilla Public Licence (MPL) v. 2 - GNU Lesser General Public Licence (LGPL) v. 2.1, v. 3 - Creative Commons Attribution-ShareAlike v. 3.0 Unported (CC BY-SA 3.0) for works other than software - European Union Public Licence (EUPL) v. 1.1, v. 1.2 - Qu\u00e9bec Free and Open-Source Licence \u2014 Reciprocity (LiLiQ-R) or Strong Reciprocity (LiLiQ-R+). The European Commission may update this Appendix to later versions of the above licences without producing a new version of the EUPL, as long as they provide the rights granted in Article 2 of this Licence and protect the covered Source Code from exclusive appropriation. All other changes or additions to this Appendix require the production of a new EUPL version.",
"summary": "A command line utility to provide feedback on Suricata rules.",
"version": "0.3.8b0",
"project_urls": {
"bugtracker": "https://github.com/Koen1999/suricata-check/issues",
"documentation": "https://suricata-check.teuwen.net/",
"homepage": "https://github.com/Koen1999/suricata-check",
"repository": "https://github.com/Koen1999/suricata-check"
},
"split_keywords": [
"suricata",
" cli",
" rule",
" rules",
" check",
" checker",
" feedback",
" network intrusion detection"
],
"urls": [
{
"comment_text": "",
"digests": {
"blake2b_256": "588fe0900db4875045dd3e631a771773ab766bf2533874f99f7d0567b2451de3",
"md5": "5603e54c8225ba9bb3229416530d63ec",
"sha256": "fb7ad5bc91af6886b23e9f15985d55a54c7332da181182899e08f54a0ea5304a"
},
"downloads": -1,
"filename": "suricata_check-0.3.8b0-py3-none-any.whl",
"has_sig": false,
"md5_digest": "5603e54c8225ba9bb3229416530d63ec",
"packagetype": "bdist_wheel",
"python_version": "py3",
"requires_python": ">=3.9",
"size": 327926,
"upload_time": "2025-01-18T23:38:11",
"upload_time_iso_8601": "2025-01-18T23:38:11.872071Z",
"url": "https://files.pythonhosted.org/packages/58/8f/e0900db4875045dd3e631a771773ab766bf2533874f99f7d0567b2451de3/suricata_check-0.3.8b0-py3-none-any.whl",
"yanked": false,
"yanked_reason": null
},
{
"comment_text": "",
"digests": {
"blake2b_256": "0d42b06f8d0d69a66fc6c76a50094986607607d7b6542804bff6e0bb1a07ee36",
"md5": "1633b9dd4786bb8d7b8d315d3debb8bb",
"sha256": "d8058cdf5e5aff28af43f8ea9a420b6c4f994b7b2f6e756efb1e3b8aa9d780b3"
},
"downloads": -1,
"filename": "suricata_check-0.3.8b0.tar.gz",
"has_sig": false,
"md5_digest": "1633b9dd4786bb8d7b8d315d3debb8bb",
"packagetype": "sdist",
"python_version": "source",
"requires_python": ">=3.9",
"size": 292428,
"upload_time": "2025-01-18T23:38:14",
"upload_time_iso_8601": "2025-01-18T23:38:14.206567Z",
"url": "https://files.pythonhosted.org/packages/0d/42/b06f8d0d69a66fc6c76a50094986607607d7b6542804bff6e0bb1a07ee36/suricata_check-0.3.8b0.tar.gz",
"yanked": false,
"yanked_reason": null
}
],
"upload_time": "2025-01-18 23:38:14",
"github": true,
"gitlab": false,
"bitbucket": false,
"codeberg": false,
"github_user": "Koen1999",
"github_project": "suricata-check",
"travis_ci": false,
"coveralls": false,
"github_actions": true,
"requirements": [
{
"name": "setuptools",
"specs": [
[
">=",
"70.0.0"
]
]
},
{
"name": "wheel",
"specs": [
[
">=",
"0.43.0"
]
]
},
{
"name": "setuptools-git-versioning",
"specs": [
[
">=",
"2.0.0"
]
]
},
{
"name": "click",
"specs": [
[
">=",
"8.1.8"
]
]
},
{
"name": "idstools",
"specs": [
[
">=",
"0.6.5"
]
]
},
{
"name": "tabulate",
"specs": [
[
">=",
"0.9.0"
]
]
},
{
"name": "regex",
"specs": [
[
">=",
"2024.5.15"
]
]
},
{
"name": "pytest",
"specs": [
[
">=",
"8.2.1"
]
]
},
{
"name": "pytest-cov",
"specs": [
[
">=",
"5.0.0"
]
]
},
{
"name": "flake8",
"specs": [
[
">=",
"7.1.0"
]
]
},
{
"name": "ruff",
"specs": [
[
">=",
"0.4.9"
]
]
},
{
"name": "black",
"specs": [
[
">=",
"24.4.2"
]
]
},
{
"name": "pyright",
"specs": [
[
">=",
"1.1.367"
]
]
},
{
"name": "sphinx",
"specs": [
[
">=",
"7.3.7"
]
]
},
{
"name": "sphinx-rtd-theme",
"specs": [
[
">=",
"2.0.0"
]
]
},
{
"name": "myst-parser",
"specs": [
[
">=",
"3.0.1"
]
]
},
{
"name": "sphinx-click",
"specs": [
[
">=",
"6.0.0"
]
]
},
{
"name": "sphinx-autoapi",
"specs": [
[
">=",
"3.4.0"
]
]
},
{
"name": "numpy",
"specs": [
[
">=",
"1.26.4"
]
]
},
{
"name": "pandas",
"specs": [
[
">=",
"2.0.3"
]
]
},
{
"name": "scikit-learn",
"specs": [
[
"==",
"1.5.1"
]
]
},
{
"name": "xgboost",
"specs": [
[
"==",
"2.0.3"
]
]
}
],
"lcname": "suricata-check"
}